CVE-2024-10451
Executive Summary
CVE-2024-10451: Keycloak’s build process can embed sensitive runtime values (e.g., passwords) as default bytecode values. In v26, environment variables used during build are stored as defaults, and indirect SPI/Quarkus property usage also expands env vars, exposing secrets at runtime across all versions up to 26.0.2. This leads to unintended information disclosure.
Authoritative CVE Metadata - CVSS Base Score: 5.9 (MEDIUM) - Published: 2024-11-25T08:15:07.900 - Last Modified: 2026-08-31T01:16:43.147
Original Description: A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process and embedded as default values in bytecode, leading to unintended information disclosure. In Keycloak 26, sensitive data specified directly in environment variables during the build process is also stored as a default values, making it accessible during runtime. Indirect usage of environment variables for SPI options and Quarkus properties is also vulnerable due to unconditional expansion by PropertyMapper logic, capturing sensitive data as default values in all Keycloak versions up to 26.0.2.
"To accomplish great things, we must not only act, but also dream; not only plan, but also believe."
— Anatole France